cncf / cncf/clomonitor

Add "Security" check: project has published a CVE

Open
#30 1 comment 0 reactions 0 assignees View on GitHub
area/core new check on hold
Dominant language
TypeScript
Stars
149
Forks
106
Avg merge
15h 4m
Merged PRs (30d)
4

Description

We should check that a project has published a CVE

https://github.com/containerd/containerd/security/advisories

It shouldn't have a ton of weight but it's a good practice for projects to do so

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the linked containerd security advisories and the repository's existing project-health checks. Determine how a published CVE should be detected and weighted, then verify that the new Security check reports projects with and without a published CVE as intended.

Written by the indexing model from the issue text.

Assessment

Tech stack
github, typescript
Domain
security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.